Skip to content
View yohanes's full-sized avatar

Highlights

  • Pro

Block or report yohanes

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

security

99 repositories

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create informational content in multiple formats and share with …

541 102 Updated Aug 4, 2022

awesome list of browser exploitation tutorials

2,241 302 Updated Sep 18, 2023

A proper well structured documentation for getting started with chrome pwning & v8 pwning

201 18 Updated Jul 27, 2022

一款自动对字节码中的字符串进行加密Android插件工具

Java 1,957 385 Updated Jul 9, 2024

this is a kernel module which connects to the apple authentication chip through i2c and expose its io through sysfs

C 6 1 Updated Jul 15, 2021

Arduino библиотека для подключения к чипам внутри Lightning

C++ 1 2 Updated Aug 8, 2022

2nd Gen Powerful Scriptable DNS server with SBL/SURBL functionality. LGPL.

PHP 5 Updated Jun 8, 2017

An implementation of function patching for iOS, without the use of W|X pages.

Objective-C 270 36 Updated Jan 20, 2013

Obtain GraphQL API schema even if the introspection is disabled

Python 1,324 120 Updated Dec 5, 2025

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

Python 1,594 217 Updated Mar 11, 2024

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetN…

PowerShell 6,126 2,078 Updated Jan 25, 2025

A little bit less hackish way to intercept and modify non-HTTP protocols through Burp & others.

Python 214 32 Updated Apr 26, 2022

Another Windows Local Privilege Escalation from Service Account to System

C++ 932 105 Updated Nov 12, 2022

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

PowerShell 2,662 477 Updated Dec 12, 2024

Minimal FIDO2 library for microcontrollers

C 19 7 Updated Aug 31, 2022

Let's sudo by face recognition of Windows Hello on Windows Subsystem for Linux (WSL). It runs on both WSL 1 and WSL 2. This is a PAM module for Linux on WSL.

Rust 1,282 53 Updated May 21, 2023

Decrypts an encrypted Bitwarden data.json file.

Python 323 44 Updated May 14, 2025

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Python 3,381 526 Updated Jan 19, 2025

一款轻量级、高性能、功能强大的内网穿透代理服务器。支持tcp、udp、socks5、http等几乎所有流量转发,可用来访问内网网站、本地支付接口调试、ssh访问、远程桌面,内网dns解析、内网socks5代理等等……,并带有功能强大的web管理端。a lightweight, high-performance, powerful intranet penetration proxy serv…

Go 33,767 6,055 Updated May 30, 2024

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.

2,720 381 Updated Nov 15, 2025

SharpUp is a C# port of various PowerUp functionality.

C# 1,438 266 Updated Feb 14, 2024

Directory Services Internals (DSInternals) PowerShell Module and Framework

C# 1,875 278 Updated Dec 14, 2025

BloodyAD is an Active Directory Privilege Escalation Framework

Python 2,035 195 Updated Dec 11, 2025

Get back online, activate, and install updates on your legacy Windows PC

C++ 1,171 45 Updated Dec 22, 2025

Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.

C 7,779 584 Updated Dec 17, 2025

A reverse engineering tool for decompiling and disassembling the React Native Hermes bytecode

Python 881 77 Updated Nov 26, 2025

This map lists the essential techniques to bypass anti-virus and EDR

2,968 331 Updated Mar 28, 2025

This is a one-time signature verification bypass. For persistent signature verification bypass, check https://github.com/TomKing062/CVE-2022-38691_38692

C 490 69 Updated Jun 14, 2025

Bad Spin: Android Binder Privilege Escalation Exploit (CVE-2022-20421)

C 273 43 Updated May 27, 2023

Exploits for Android Binder bug CVE-2020-0041

C 252 73 Updated Apr 8, 2020